INTERNSHIP DETAILS

Intern, SIEM Engineer

CompanyEnsign Services
LocationIndonesia
Work ModeOn Site
PostedAugust 3, 2026
Internship Information
Core Responsibilities
The intern will assist in integrating log sources, developing detection rules, and creating dashboards within the SIEM platform. They will also support the SOC team with alert triage, log parsing, and incident investigation documentation.
Internship Type
full time
Company Size
4058
Visa Sponsorship
No
Language
English
Working Hours
40 hours
Apply Now →

You'll be redirected to
the company's application page

About The Company
Skilled Nursing/Assisted Living
About the Role

Ensign is hiring !

Key Responsibilities

  • Log Source Onboarding: Assist in integrating new log sources (servers, firewalls, endpoints, cloud services, applications) into the SIEM platform.
  • Use Case / Detection Rule Development: Help build, test, and tune correlation rules, alerts, and detection use cases to identify suspicious or malicious activity.
  • Dashboard & Report Creation: Create and maintain dashboards, visualizations, and reports for security monitoring and compliance purposes.
  • Alert Triage & Tuning: Support the SOC team in reviewing alerts, reducing false positives, and improving signal-to-noise ratio.
  • Log Parsing & Normalization: Assist with parsing, normalizing, and enriching raw log data so it's usable for analysis.
  • Documentation: Document SIEM configurations, standard operating procedures (SOPs), playbooks, and detection logic.
  • Incident Support: Assist analysts during security incident investigations by pulling relevant logs/queries from the SIEM.
  • Health Monitoring: Help monitor SIEM system health, data ingestion rates, and license/storage usage.
  • Research: Stay current on emerging threats, MITRE ATT&CK techniques, and translate them into new detection content.
  • Compliance Support: Assist with audit and compliance log retention/reporting requirements (e.g., PCI-DSS, ISO 27001, SOC 2).
     

Required / Preferred Skills

  • Basic understanding of networking (TCP/IP, DNS, firewalls) and operating systems (Windows/Linux).
  • Familiarity with security concepts: threat detection, incident response, log analysis.
  • Exposure to at least one SIEM tool (Splunk, QRadar, Sentinel, ELK/Elastic) — coursework, labs, or certs count.
  • Basic scripting/query language skills (SPL, KQL, Python, or regex).
  • Understanding of common attack techniques (phishing, malware, lateral movement) — MITRE ATT&CK familiarity is a plus.
  • Analytical thinking, attention to detail, and good documentation habits.
  • Currently pursuing a degree in Cybersecurity, Computer Science, IT, or related field.
     

Nice-to-Have

  • Certifications: Security+, CySA+, Splunk Fundamentals, or similar.
  • Experience with cloud security (AWS/Azure/GCP logging).
  • Prior CTF, home lab, or SOC simulation experience.
     

Learning Outcomes for the Intern

  • Hands-on SIEM administration and content development experience.
  • Real-world exposure to SOC workflows and incident response.
  • Understanding of enterprise logging architecture and detection engineering lifecycle.
Key Skills
SIEMLog AnalysisThreat DetectionIncident ResponseNetworkingTCP/IPDNSFirewallsSplunkQRadarSentinelELKPythonRegexMITRE ATT&CKCybersecurity
Categories
Security & SafetyTechnologySoftwareData & Analytics